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LISTING OF CLAIMS 

This listing of claims will replace all prior versions, and listings, of cflaims in the application: 



1 . (Original): A method for controlling access, use and distribution of personal data of a 
user stored in a personal repository, the method comprising the steps of: 

allowing a user to indicate which portions of the persoryil data stored in the personal data 
repository are releasable to a second party; 

reaching an agreement, between the user and the secofid party, regarding use, by the 
second party, of any portions of the personal data in the per^nal data repository; and 

releasing any of the portions of the stored personal ^ata in the personal data repository to 
the second party according to the agreement, wherein 

the agreement includes what items within the personal data repository can be used by the 
second party, and 

only ones of the items which, accor^tiigto the^^eement, can be used by the second party 
are released to the second party. 



2. (Original): The method of claim 1^ 
collected automatically. 



2in the pbfsonal data about the user is 



3. (Original): The method of claim 1, vM^jpsm the step of reaching the agreement 
comprises choosing an agreement provided by an independent agreement provider, wherein the 
independent agreement provider receives compensation based on use of the provided agreement. 

4. (Original): The method of claim ll wherein the personal data about the user is entered 
by the user. 



5. (Original): The method of claim j, further comprising the step of storing the personal 
data about the user on a device operated by the user. 
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6. (Original): The method of claim 1 , further comprising the step of storing the personal 
data about the user on a trusted party device, 

1. (Original): The method of claim 1 , further comprising the step of storing the personal 
data about the user in a distributed manner among a plurality of trusted party devices. 

8. (Original): The method of claim 1 , further cofiprising the step of allowing the user to 
perform at least one of adding, deleting or changing the Personal data about the user. 



9. (Original): The method of claim 1 , further comprising the step of defining a service 
profile within the personal data repository, whefem the service profile includes portions of the 
personal data of the user and information reg^ding oond^ions under which items within the 
service profile can be used by the second pa 



10. (Original): The method of claini 9, wherein^e service profile includes information 
regarding a date and a time that any of the stofedpiformation about the user was released to the 
second party and to whom the stored information was released. 

1 1 . (Original): The method of claim 9, wherein the service profile includes information 
pertaining to a description of the agreement benveen the user and the second party. 

12. (Original): The method of claim 1/, further comprising the step of acting, by a trusted 
party, as an agent of the user to negotiate use, by the second party, of any of the personal data of 
the user in return for compensation to the user for the use of any of the personal data. 



13. (Original): The method of claim 1, further comprising the steps of recording a history 
of actions, by the user using a user device, as part of the personal data of the user. 
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14. (Original): The method of claim 13, further comprising defining, by the user, of a 
level of a type of the actions to be recorded. 

15. (Original): The method of claim 1 , further/comprising the steps of: 
receiving, at a trusted party device connected/to a computer network, a first request from 

a device operated by a user; 

forming a second request from the first reqiiest, the second request being stripped of 
information that can associate the user with the second request; 

sending, from the trusted party device, th^ second request over a computer network to a 
second party device; 

receiving, at the trusted party device, res^jonse information in response to the sending of 
the second request; 

forming a response based on thd^dspoiis^ information; and 
sending the response to the device} opened by the user. 

16. (Canceled) 

1 7. (Original): A method of controlling receipt of information, comprising the steps of: 
receiving, by a user device from a second party device, a request for at least some of the 

personal data of the user; 

attempting to reach an agreement \^ith a second party, via the second party device, 
regarding use by the second party of any off the personal data of the user; and 

sending information to the user device only if the agreement is reached. 

18. (Presently amended): A system for providing personal data of a user with access rights 
being controlled by the user, the system^ comprising: 

a user device; 

a trusted party device, the user jlievice being arranged to communicate with the trusted 
party device; 
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at least one data storage device including the personal data of the user; 

a rules enforcer included in the trusted party device to enforce rules by which the personal 
data of the user can be accessed and used by a second party device, the rules having been agreed 
to by the user and a second party associated with the second party device, wherein: 

the at least one data storage device is associate^ with at least one of the user device and 
the trusted party device. 

1 9. (Original): The system of claim 1 8, furtper comprising a plurality of trusted party 
devices, each of the trusted party devices being configured to communicate with at least one 
other of the plurality of trusted party devices, wherein: 

the at least one storage device is includes in at least some of the plurality of trusted party 
devices and the personal data of the iss6risdiWibuted among the at least one storage device of 
the at least some of the plurality of trusted party dtevices. 

20. (Original): The system of jj^i^^, wh^in the trusted party device further comprises 
an agreement facilitator to facilitate an agreement between the user and the trusted party. 

2 1 . (Original): The system olclWrl^, wherein the user device further comprises an 
agreement facilitator to facilitate an agreement between the user and the trusted party. 



22. (Original): The system of c^im 18, wherein the at least one data storage device has 
recorded therein a service profile within a personal data repository, wherein the service profile 
includes portions of the personal data/of the user and information regarding conditions under 
which items within the service profile can be used by the second party. 



23. (Original): The system of claim 18, wherein the trusted party device further comprises 
a history recorder to record a history of actions performed by the user device. 

24. (Original): The systerp of claim 23, wherein the history recorder includes a level 
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selector by which the user, via the user device, can select one of a plurality of levels of a type of 
the actions to be recorded. / 

25. (Original): A system for providing personal data of a user with access rights being 
controlled by the user, the system comprising: / 

a user device; / 

a second party device, the user device being arranged to communicate with the second 
party device; / 

a data storage, associated with the user devide, including the personal data of the user; 
and / 

a rules enforcer included in the user device jto enforce rules by which portions of the 
personal data of the user can be accessed by the second party device, the rules having been 
agreed to by the user and a second party a^sfeciatecl whh the second party device, the rules 
including what items of the personal data are releasable \o the second party and how the items of 
the personal data can be used by the second partyJ / 

26. (Original): The system of claim 25, ftrther yomprising a service profile stored within 
the data storage, the service profile including poitiprfs of the personal data of the user and 
information pertaining to an agreemeriTdescnDir g how any of the stored information about the 
user can be used by the second party. 



27. (Original): The system of claim 25, wherein the user device further comprises a 
history recorder to record a history of actions performed by the user device. 



28. (Original): The system of claim 27, wherein the history recorder includes a level 
selector to select one of a plurality of levels of a type of the actions to be recorded. 

29. (Presently amended): A device for pro ading personal data of a user with access and use 
rights being controlled by the user, the device iomprising: 
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user; 



and 



a data storage device having recorded therein at least/some of the personal data of the 



an agreement facilitator to facilitate an agreement ^between the user and a second party; 



a rules enforcer to enforce rules by which items/of the personal data of the user can be 
accessed and used b y a second party device, the rules having been agreed to by the user and a 
second party associated with the second party devica the rules enforcer allowing access to only 
ones of the items, which according to the agreement, can be used by the second party. 



30, (Original): The device of clairn22aWllerein the data storage device has recorded 
therein a service profile within a personal lata repository, the service profile including portions 
of the personal data of the user and information regarding conditions under which items of the 
stored personal data of the user can be releaseilto the second party. 



3 1 . (Original) : The device of claim 
information regarding a date and a time th; 
released to the second party. 



fo, wherein the service profile is arranged to include 
any of the stored personal information of the user is 



32. (Original): The device of cMm 30, wherein the service profile is arranged to include 
information pertaining to a contract that describes how any of the stored personal data of the user 
can be used by the second party. 

33 . (Original): The device of c laim 29 further comprising a history recorder to record a 
history of actions performed by the u! er. 

34. (Original): The device of ilaim 33, wherein the history recorder includes a level 
selector by which the user can select ^ne of a plurality of levels of a type of the actions to be 
recorded. 
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35. (Original): A mobile device for providing personal data of a user with access rights 
being controlled by the user, the mobile device comprising^ 

a rules enforcer to enforce the rules by which the personal data of the user can be 
accessed by a second party device, the rules having been agreed to by the user and a second party 
associated with the second party device; 

a data storage device having recorded therein least some of the personal data of the 

user; 

an agreement facilitator to facilitate an agrcjiment between the user and the second party, 
wherein: 

the data storage device is arranged to hav^ recorded therein a service profile including 
portions of the personal data of the us^ ajuLinfiormation regarding conditions under which items 
within the service profile can be use^l)^ the sf ojnd party. 

36. (Original): A machine-readable jnedjfum having recorded thereon instructions of a 
processor in a device to perform the steps 

receiving an indication regarding Miich portilsns of personal data of a user stored in a 
personal data repository are releasable to a second party; 

reaching an agreement, between the user and the second party, regarding use, by the 
second party, of any portions of the pM-sonal jkta in the personal data repository; and 

releasing any of the portions of the stored personal data in the personal data repository to 
the second party according to the agreement, wherein 

the agreement includes what/ items within the personal data repository can be used by the 
second party, and / 

only ones of the items which, according to the agreement, can be used by the second party 
are released to the second party. 

37. (Original): The machine-readable medium of claim 36, further comprising 
instructions for storing of the personal data about the user in a distributed manner, the personal 
data being distributed and stored among a plurality of devices arranged to communicate with one 
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another. 



38. (Original): The machine-readable medium of cMm 36, further comprising 
instructions for allowing the user to perform at least one o; adding, deleting or changing the 
personal data about the user. 




39. (Original): The machine-readable mediuni/of claim 36, further comprising 
instructions for allowing a defining of a service profile within a personal data repository, the 
service profile including portions of the personal data of the user and information regarding 
conditions under which items of the stored perso;lal data of the user can be released to the second 
party. 

40. (Original): The machine-readaftlo^me/dium of claim 39, wherein the service profile 
includes information pertaining to the agreenj^rrt-h^tween the user and a second party. 



41. (Original): The machine-readabla medium of claim 36, further comprising 
instructions for recording a history of actions\by the jiser as part of the personal data of the user. 

42. (Original): The machineyreadable medium of claim 41, further comprising 
instructions for defining, by the usj&r, a level of a type of the actions to be recorded. 

43. (Canceled) 



44. (Original): A machine-readable medium having recorded thereon instructions for a 
processor in a device to perform the steps of: 

receiving, by a user ^evice fi*om a second party device, a request for at least some of the 
personal data of the user; 

attempting to reachf an agreement with a second party, via the second party device, 
regarding use by the second party of any of the personal data of the user; and 
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sending vendor information to the user device only if the agreement is reached. 



45. (Presently amended): A mobile device for providing personal data of a user with access 
rights being controlled by the user, the mobile device comprismg: 

a rules enforcer to enforce the rules by which the personal data of the user can be 
accessed and used b y a second party device, the rules havi)/g been agreed to by the user and a 
second party associated with the second party device; 

a data storage device having recorded therein at/least some of the personal data of the 



user; 




an agreement facilitator to facilitate a 

( 

a history recorder to record a history o 



af^efmfent between the user and the second party; 



tions/by the user via the user device, the history 
recorder including a level selector to select a lbVel^£the actions to be recorded, wherein: 

the data storage device is arranged to have recordeotherein at least a portion of a service 
profile including information regarding what portions of tjae stored personal data of the user can 
be released to the second party and conditpns ujpder ^ch the portions of the service profile can 
be released to the second party. 




46. (New) A trusted party device for providing personal data of a user with access rights being 
controlled by the user, the trusted party device comprising: 

an anonymizer to remove information that identifies the user from a first message sent from a 
user device to a second party device; 

a transmitter to transmit the first message to the user device or to the second party device; 
a receiver to receive a second message from the user device, or from the second party device; 
a data editor allowing the user, via the user device connected to the trusted party device via a 
network, to create a data profile, to indicate a first portion of the data profile that may be accessed 
and used, to indicate a secono party that may access and use the first portion of the data profile, to 
indicate a time period during which the first portion of the data profile may be accessed and used by 
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the second party, to change the first portion of the data profile, and/to delete the first portion of the 
data profile; 

a data storage device that contains the first portion of the rfata profile, or a second portion of 
the data profile; 

a network interface device to connect the trusted party yflevice to the network; 
an agreement facilitator to facilitate an agreement between the user and the second party 
regarding use of personal information of the user stored in the data profile; 

a rules enforcer to enforce the agreement between the user and the second party, allowing the 
second party to access only the first portion of the data profile, and to use the first portion of the data 
profile only during the time period specified by the user; and 

an automatic information collector to cj^pure the^ersonal information of the user and to 
automatically create or add the personal information o^the ilper to the data profile. 

47. (New) A user device for providing persona^ d^j3r6f'a<user with access rights being controlled 
by the user, the user device comprising: 

an anonymizer to remove information that identifies the u^r from a message sent from the 
user device to a second party device; 

a data editor allowing the user, via the use/ deViceJ<? create a data profile, to indicate a first 
portion of the data profile that may be accessed andiis^a, to indicate a second party that may access 
and use the first portion of the data profile, to indicate a time period during which the first portion of 
the data profile may be accessed and used by the second party, to change the first portion of the data 
profile, and to delete the first portion of the data profile; 

a data storage device that contains the/first portion of the data profile or a second portion of 
the data profile; 

a network interface device to connect the user device to a network; 
an agreement facilitator to facilitate an agreement between the user and the second party 
regarding use of personal information of the user that is stored in the data profile; 
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a rules enforcer to enforce the agreement between the user and the second party, allowing the 
second party to access only the first portion of thedatp^rofile, and to use the first portion of the data 



profile only during the time period specified^y the 

an automatic information colle 
automatically create or add the personal infomiati^ 



lisot; and 

collect the personal information of the user and 
abom the user to the data profile. 
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